Hi Team
I would like to clarify a few points regarding the On Ramp configuration in FortiSASE.
If the license covers 2 instances and 400 connections, is it recommended to deploy 2 instances and distribute 200 connections each? If the customer has only 180 locations, can we establish 2 tunnels (one to each instance) and use them for load balancing or configure them as primary and secondary?
Is there any documentation available for configuring Aruba to FortiSASE On Ramp tunnels?
Regarding tunnel IPs: is it mandatory to configure them? I understand it is required when using policy routing on the on-prem FortiGate, but are there other cases where it matters? Do we need Mode Config with DHCP-assigned IPs for FortiGate and Aruba SD-WAN gateways, and is this fully supported?
Thank you
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi @Sambhu ,
1) For this you want to setup 2 SASE instance and each one will have 180 connection.
from each branch 2 tnl will be setup towards each sase instance
You can setup as primary and secondary for proper failover
2) You may refer below article for VPN config on SASE:
https://docs.fortinet.com/document/fortisase/latest/feature-administration-guide/213023/on-ramp-tunn...
There is no specific document with aruba but the VPN config remains the same regardless of vendor, though there may be some adjustment based on certain vendor of specifying local id or peer id.
3) As per below article mode config is needed
https://docs.fortinet.com/document/fortisase/latest/feature-administration-guide/796374/ipsec-config...
Thanks a lot Salon.
User | Count |
---|---|
2574 | |
1373 | |
796 | |
657 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.